can we perform HIP check for domain without GP license
we want to enable HIP check only to detect domain of machines. is it possible to achieve without GP gateway license. Below highlighted option want to enable in compliance.
we want to enable HIP check only to detect domain of machines. is it possible to achieve without GP gateway license. Below highlighted option want to enable in compliance.
Hi Guys, already have raised support ticket but no reply for few days, so trying to get some info here. I have seen couple of threads but not sure they are related to issue we have with these few Win10 laptops. We have Palo VM on 10.0.6 OS and GP is 5.2.10-6 .We have few users having problem with GP. From what we can see, is affecting only Win1...
hi all, new to the palo alto world, however i cannot seem to find info on setting up globalprotect to use the windows store version of the GP app. I've ot the subscription licence applied to my firewall and went throuhg the pocess of creating a clientless vpn connection to no avail.if i use the globalprotect client that i download that works fin...
Hi Team, We have a requirement to configure the Global Protect as below. > We have 3 locations to connect to. Users should connect to one of these 3 locations based on their nearby location. If User 1 is near to GW3 then he should connect to GW3. If GW3 is not available, then the next nearest location should be connected automatically. Is th...
I am trying to setup Global Protect Portal authentication using Client Certificate Authentication instead of radius. I generated CA and self signed cert on the palo. Configured Client Cert profile and attached it to Portal -> Authentication (removed Radius auth) and selected Client Cert profile. Also downloaded and installed the Cert and root...
Hello to everyone,In my environment, the GP is set as always on and it works properly. The problem is that some clients have started demanding that we access them through the VPN client they provide us with.I know there is an option to allow the user to disable GP but I would like to avoid that.Has anyone encountered a similar requirement or is ...
Hello Team, All of the mac users are getting authentication issue errors on their screen and unable to enter the credentials. The pop window is blank. Kindly find the gp logs below: P41029-T12039 Oct 11 13:52:35:203760 Debug(2142): ----portal processing starts----P41029-T12039 Oct 11 13:52:35:203764 Debug(2164): User profile type is 0(not ro...
Hello, I'm a help desktop tech. I have a user who is asking why he is receiving this error message. I'm not sure myself, can someone explain it to me. Thank you
Hi everyone, on PA-220 I've update firmware version from 10.1.5h1 to 10.2.2.We have globalprotect work with Radius Authentication with protocol PEAP-MSCHAPv2.After the upgrade it doesn't work anymore. (it works with other protocol, like PAP). Certificates are ok, nothing changed.We've already tried to change radius server without success.This is...
Hi Running into issue with prelogon not working properly. I have pretty much mirrored the configuration from this KB - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0 Scenrio - when Laptop is connected to On prem production wifi - Internal host detection with enforece network access ON- when the laptop boots...
Anyone know where to look for the GP login rate? For example, how many users are logging on per sec, min, hour, day?
Hi! I was reading 'Gateway Priority in a Multiple Gateway Configuration'. So far, so good. My question is - when were running multiple gateways on appliances restricted to i.e. 1000 gp clients. What happens if the best available gateway (highest prio & lowest response time) is at its maximum capacity? Does it 'tell' the client to choose ano...
I'm having problems getting pre-logon to work on MacOS. There are a number of issues.- To start with, I can't seem to get the GlobalProtect icon from the login screen after several tries.- Then, even when I log in to the device and try to connect to GlobalProtect, I get prompted for keychain access so that GlobalProtect can access the machine ce...
Hi Team, Is there a best way to find out the user's who is using lower version of the Global Protect client. apart from Global Protect Logs.
How do you allow GlobalProtect users connected to the network access to the internet through the firewall on which GP is configured?

